Skip to content

release: configure npm trusted publishing for all 8 @curatelabs packages #438

Description

@DecisionNerd

Summary

Migrate GraphForge npm publication from long-lived NPM_TOKEN (Bypass 2FA) to npm trusted publishing (GitHub Actions OIDC) with provenance attestations, matching PyPI and crates.io.

Acceptance criteria (in-repo)

  • publish.yaml npm jobs have id-token: write and do not project NPM_TOKEN / NODE_AUTH_TOKEN
  • scripts/publish_npm_artifacts.py publishes with --provenance and routes --package through integrity-resume (publish_one)
  • release-credential-preflight.yml and contract tests assert the OIDC / no-token model
  • Docs (publication-order.md, RELEASING.md, v0.5 runbook) drop Bypass-2FA / NPM_TOKEN requirements and document npm trusted publishing like PyPI/crates
  • Publish-once / attempt-receipt semantics are unchanged

Human console steps (before first OIDC npm publish)

On npmjs.com, configure a GitHub Actions trusted publisher for each of the 8 @curatelabs packages:

  1. @curatelabs/graphforge-darwin-arm64
  2. @curatelabs/graphforge-darwin-x64
  3. @curatelabs/graphforge-linux-arm64-gnu
  4. @curatelabs/graphforge-linux-x64-gnu
  5. @curatelabs/graphforge-win32-x64-msvc
  6. @curatelabs/graphforge
  7. @curatelabs/graphforge-cli
  8. @curatelabs/graphforge-agent-skills

For each package → Package Settings → Trusted Publisher → GitHub Actions:

  • Owner: CurateLabs
  • Repository: graphforge
  • Workflow filename: publish.yaml
  • Environment: leave blank (same as PyPI)

Also confirm the @curatelabs org allows OIDC trusted publishing. For any package that does not yet exist, use npm’s pending trusted-publisher / first-publish flow.

Retire NPM_TOKEN

Only after a successful publish.yaml npm lane authenticates via OIDC:

gh secret delete NPM_TOKEN --repo CurateLabs/graphforge

Rotate any local copies of the former granular Bypass-2FA token.

Out of scope

  • Binding RC Bazel cutover
  • publish.yaml concurrency / environment keys / stale tag defaults
  • Changing publish-once / attempt-receipt semantics

References

  • Devinfra Audit priority: npm trusted publishing + provenance

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions